Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 375

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Anthropic launches cheaper AI model, its second release since CEO's call for a slowdown
CNBC's The China Connection newsletter: Spectacle-heavy Trump-Xi summit was more about domestic messaging
Meta's splashy new business AI hire offers yet another reason to bank on Zuckerberg
The warning signs your debt may be a problem, according to a credit counselor — and what to do first
A key test looms for the AI trade this week. Here's how Mike Khouw is trading it
Movie: Wrong Turn
San Diego Restaurants, Events, Fun Suggestions
A relief rally could be coming soon for these stocks getting hurt by higher rates, says Katie Stockton
Boeing 737 Max 10 certification delayed by software issue, FAA says
LeBron James is already boosting ticket and merchandise demand for Philadelphia 76ers